[
https://issues.apache.org/jira/browse/KNOX-3389?focusedWorklogId=1031659&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1031659
]
ASF GitHub Bot logged work on KNOX-3389:
----------------------------------------
Author: ASF GitHub Bot
Created on: 22/Jul/26 12:15
Start Date: 22/Jul/26 12:15
Worklog Time Spent: 10m
Work Description: github-actions[bot] commented on PR #1318:
URL: https://github.com/apache/knox/pull/1318#issuecomment-5045645387
## Test Results
40 tests 40 ✅ 4s ⏱️
3 suites 0 💤
3 files 0 ❌
Results for commit 1e259629.
[test-results]:data:application/gzip;base64,H4sIAEi0YGoC/12Myw6CMBBFf4V07aIPQOrPmLFOk4lATR8r4r87oPJwd8+5yZmEpx6TuFTmVIlUKK9wLxEyhZGxZuQjz1ctf3BNxbk/86Anm014oP4gMMYQvyaWcS3O+xD8iK238C638L7mwjBQZhAKdWNbbXWL/mxAobSInbpJ8F4a3aF0jQKD4vUG8xd2QP8AAAA=
Issue Time Tracking
-------------------
Worklog Id: (was: 1031659)
Time Spent: 0.5h (was: 20m)
> Embedded LDAP getUserGroups drops roles-lookup roles that have no backing
> group
> -------------------------------------------------------------------------------
>
> Key: KNOX-3389
> URL: https://issues.apache.org/jira/browse/KNOX-3389
> Project: Apache Knox
> Issue Type: Bug
> Components: Server
> Affects Versions: 3.0.0
> Reporter: Sandor Molnar
> Assignee: Sandor Molnar
> Priority: Major
> Fix For: 3.0.0
>
> Time Spent: 0.5h
> Remaining Estimate: 0h
>
> When the embedded Knox LDAP server has the roles lookup interceptor enabled,
> resolved roles are written to the user entry as memberOf values. If the user
> has no existing groups (so there is no template group DN to build a full DN
> from), {{LDAPRolesLookupInterceptor.addRoleAttribute}} stores each role as a
> bare RDN, e.g. {{memberOf: cn=platform:awc-admin-sam}}, with no trailing DN
> components.
> {{KnoxLDAPServerManager.getUserGroups}} then fails to return these as groups.
> It extracts the CN by taking the substring between {{cn=}} and the first
> comma, but a bare RDN has no comma {{(indexOf(',') returns -1)}}, so the
> value is silently skipped and the roles never surface as groups.
> *Repro:* embedded LDAP pointed at a demo backend whose LDIF defines users but
> no groups, with {{rolesLookup}} in {{gateway.ldap.interceptor.names}}.
> Authenticate a user (e.g. {{sam}}) whose roles resolve to
> {{platform:awc-admin-sam}} and {{ml-workspace-abc:viewer-sam}}. Knox resolves
> the roles and writes them to {{memberOf}} as {{cn=<role>}}, but
> {{getUserGroups("sam")}} returns an empty list.
> *Fix:* when the roles lookup interceptor is active, handle bare-RDN
> {{memberOf}} values by taking everything after {{cn=}}. Full DNs continue to
> be parsed as before, and a no-comma value without the interceptor is still
> skipped as unexpected data.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)